You have just found a data breach. The clock is already running. Here, step by step and without panic, is what to do and what comes next.
A data breach does not necessarily mean a movie-style attack. Most of the time it is something mundane: an email sent to the wrong person, a lost laptop, a file accessed by someone who should not have. The good news is that the law does not punish you for having an incident, it punishes you for not responding properly. And the proper response has clear steps.
It is any situation where personal data ends up where it should not, is lost, altered or no longer available. Three kinds, in short:
The rule comes from Article 33 of the GDPR and is simpler than it sounds. You look at one thing: can the breach harm people?
Whatever you decide, every breach goes into an internal incident register. It is proof you treated things seriously, and the authority can ask for it at any time.
Not from when the breach happened, but from when you became aware of it with reasonable certainty. Important to know: the clock runs continuously, including weekends and holidays. That is exactly why it is best to have a plan in advance, rather than inventing one on a Saturday night.
If you cannot make it within 72 hours, you still send the notification, but you add the reason for the delay. A late but honest notification is far better than silence.
In Romania, the notification is made through the breach notification form on the authority's website, dataprotection.ro. The law requires the notification to include, in plain terms:
You do not need all the perfect answers from the start. If you are still investigating within 72 hours, you send what you know now and come back with the rest in phases. That is perfectly accepted.
Besides the authority, sometimes you also have to inform the people whose data was affected. This comes from Article 34 and applies when the breach can pose a high risk to them: fraud, identity theft, exposure of sensitive data.
The message to people has to be clear, not a legal text. You tell them what happened, what data is involved and what they can do to protect themselves (for example, change a password or watch out for suspicious messages). If the data was encrypted or you have since taken measures that make the risk unlikely, individual notice may no longer be needed.
Once you send the notification, things can go several ways.
Here, how you behaved matters enormously: a timely, honest notification, with measures already taken and an orderly record of the incident, weighs strongly in your favour. Panic and hiding do exactly the opposite.
The calmest companies during a breach are not the ones that never make mistakes, but the ones that know in advance who does what in the first hours. At INFOSHARE we prepare an incident response plan, the breach register and the notification texts together, and if a real incident happens, we walk you through the whole process. See our GDPR services, the outsourced DPO role and the article on a real incident with data in an Excel file. Everything about registers and records sits in one place, in the askGDPR platform.
When the breach can pose a risk to people's rights and freedoms. You notify the authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk is unlikely, for example the data was properly encrypted, you may skip the notification, but you must write down and keep the reason for that decision.
From the moment you become aware, with reasonable certainty, that a breach has occurred, not from when it happened. The clock runs continuously, including weekends and holidays. If you cannot make it within 72 hours, you still send the notification, but you add the reason for the delay.
Through the breach notification form on the authority's website, dataprotection.ro. You describe what happened, what data and how many people are affected, the likely consequences and the measures you took. If you do not have all the details within 72 hours, you can send the information in phases.
Yes, when the breach can pose a high risk to them, for example fraud or identity theft. You tell them clearly and in plain language what happened and what they can do to protect themselves. If the data was encrypted or you have taken measures that make the risk unlikely, individual notice may no longer be needed.
You receive a confirmation and a registration number. The authority may ask for clarifications, may open an investigation or an inspection. In the end it may take no action, order remediation measures or, in serious cases, impose a fine. A timely, honest notification with measures already taken weighs strongly in your favour.
We prepare the incident response plan, the breach register and the notification texts together, so that in the first 72 hours you know exactly what to do.